First published: Wed Jun 16 2021(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and filesystem contain hard-coded default credentials. An attacker can leverage this vulnerability to execute code in the context of the download user. Was ZDI-CAN-11852.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Reason Rpv311 Firmware | =14a03 | |
Ge Rpv311 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-31477 is high, with a severity value of 7.3.
CVE-2021-31477 allows remote attackers to execute arbitrary code by exploiting a specific flaw within the firmware and filesystem of the affected device.
No, authentication is not required to exploit CVE-2021-31477.
The affected software for CVE-2021-31477 is GE Reason RPV311 14A03 firmware.
To fix CVE-2021-31477, it is recommended to follow the mitigation steps provided by the vendor in their security notice.